Legal
Privacy Policy
This Privacy Policy explains how FlowSimple collects, uses, discloses, retains, and protects personal information when you visit our website, use the FlowSimple application, receive a public estimate, or otherwise interact with the Service.
1. Scope and our role
This policy applies to the FlowSimple website and application, account and workspace administration, subscription billing, support, public estimate pages, browser push notifications, and communications sent through or about the Service. The Service is currently offered only to businesses in the United States.
FlowSimple acts as a business or controller for account, billing, security, website, support, and service-operations information. For customer, lead, employee, contractor, property, estimate, job, task, photo, signature, and other workspace information entered by a subscribing business (a “Subscriber”), FlowSimple generally acts as that Subscriber’s service provider or processor.
If a Subscriber entered your information, direct your request to that Subscriber first. We will assist it as required by applicable law and our agreement. This policy does not govern a Subscriber’s independent practices outside FlowSimple.
2. Information we collect
Depending on how the Service is used, we may collect:
- Account and identity information, including name, email, phone, profile image, business name, workspace role, verification and invitation status, password hashes, recovery records, multi-factor authentication configuration, sessions, devices, and communication preferences.
- Subscriber business information, including business profile, address, contact details, branding, timezone, tax defaults, business hours, team members, permissions, and security settings.
- Workspace content, including customers, leads, properties, notes, activities, estimates, prices, costs, schedules, jobs, routes, assignments, service plans, checklists, tasks, photos, signatures, files, recorded payment status, and imported records.
- Public estimate activity, including view dates, decision status, typed name, terms consent, optional signature, decline reason, change request, IP address, user agent, and first and last view time.
- Subscription information received from Stripe, including customer, Checkout, subscription, invoice, and event identifiers; trial and billing dates; purchased seats; amounts; payment status; cancellation state; invoice links; and limited payment-method details such as brand and last four digits.
- Website and device information, including IP address, browser and device type, operating system, language, approximate location inferred from IP, referring page, requested page, timestamps, interactions, and diagnostic information.
- Communications and support information, including contact-form submissions, assistant conversations, emails, attachments, troubleshooting details, privacy requests, and our responses.
Stripe processes complete payment-card and security-code details through its hosted interfaces. FlowSimple does not receive or store complete card numbers. Uploaded or typed signatures record estimate decisions and are not used for biometric identification, facial recognition, or profiling.
Address searches may send a query and country code to a Photon-compatible geocoding provider. Selected addresses may be stored with address-derived coordinates. FlowSimple does not currently request precise GPS location from a user’s device.
3. Sources of information
- Directly from account holders, website visitors, public estimate recipients, and people who contact support.
- From Subscribers and authorized users when they create records, upload content, invite members, or assign work.
- Automatically from browsers, devices, cookies, browser storage, logs, and security systems.
- From service providers such as Stripe, UploadThing, email and hosting providers, geocoding services, push services, and authentication infrastructure.
- From public sources or business partners when collection and use are permitted by law.
4. How we use information
- Create, authenticate, secure, and administer accounts, sessions, workspaces, roles, and permissions.
- Provide CRM, estimating, scheduling, job management, recurring work, field execution, reporting, imports, exports, and notifications.
- Generate, deliver, display, and record customer decisions on public estimates and related documents.
- Operate trials, process subscriptions, manage seats, present invoices, and reconcile Stripe billing state.
- Send verification, recovery, invitation, estimate, billing, trial, service, security, and support communications.
- Remember interface preferences and optional browser-notification choices.
- Detect, prevent, investigate, and respond to fraud, abuse, security incidents, unauthorized access, and violations of our Terms.
- Maintain audit records, debug errors, improve reliability and features, understand service performance, and support business operations.
- Comply with law and legal process, enforce agreements, establish or defend claims, and complete a corporate transaction.
We do not use Subscriber workspace content to train a general-purpose AI model. The website assistant first uses local product information. When an AI-generated answer is needed, recent conversation messages may be sent to Google Gemini. Do not submit workspace records, passwords, payment details, or other sensitive data to the website assistant.
5. How we disclose information
Workspace information is available to authorized users according to their roles and assignments. Public estimate recipients can view the estimate, Subscriber branding, contact details, and terms through a valid tokenized link. Internal notes, costs, margins, member emails, and workspace identifiers are not intended for that view.
Providers that may process information for us include:
- Vercel or another hosting provider for hosting, delivery, and operational logs, and Neon or other PostgreSQL infrastructure for databases and backups.
- Stripe for subscription Checkout, payment processing, invoices, applicable tax services, and the Customer Portal.
- UploadThing for authorized file and image upload, storage, delivery, and deletion.
- Resend or another email provider for transactional and service communications.
- Photon/Komoot-compatible services, OpenStreetMap, and user-selected map applications for address search, mapping, and directions.
- Browser push services for notifications a user chooses to enable.
- Google Gemini for website-assistant messages that cannot be answered locally.
- Discord, when configured, for limited internal delivery of website contact requests and operational notices.
We may also disclose information to professional advisers; when required by law or valid process; to protect rights, safety, property, or service integrity; at the direction or with the consent of the relevant party; or during a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets.
6. No sale or targeted advertising
FlowSimple does not sell personal information for money, share it for cross-context behavioral advertising, or process it for targeted advertising as those terms are defined by applicable US state privacy laws. If these practices change, we will update this policy and provide legally required controls before beginning them.
8. Data retention
We retain information as long as reasonably necessary to provide and secure the Service, maintain the Subscriber relationship, fulfill this policy, comply with legal and accounting duties, resolve disputes, and enforce agreements. Retention depends on the record and its context.
- Account and workspace records are generally retained while the account or workspace remains active and during any stated post-termination retention period.
- Subscription, invoice, tax, transaction, audit, fraud-prevention, dispute, and legal records may be retained after termination as required or permitted by law.
- Session, verification, invitation, recovery, and public-link records expire according to their security or product purpose.
- Public links may expire while the underlying estimate, decision, and business history remain in the Subscriber workspace.
- Deactivated users may remain associated with historical records needed for business integrity and audit history.
- Uploaded content remains while associated with workspace records, subject to authorized deletion, orphan cleanup, and backup rotation.
When information is no longer reasonably necessary, we delete, de-identify, or securely isolate it unless continued retention is required or permitted. Owners should export information they need before requesting deletion or ending service.
9. Security
We use safeguards designed to protect information, including encrypted transport, provider-managed encryption at rest, access controls, role-based authorization, secure cookies, password hashing, optional multi-factor authentication, rate limiting, audit logging, tenant-scoped access, webhook signature verification, and dependency review.
No system is completely secure. Users must protect credentials and authentication devices, configure roles carefully, and contact security@flowsimple.co promptly if they suspect compromise.
10. Your choices and rights
Depending on your residence and applicable exceptions, you may have the right to:
- Confirm whether we process your personal information and access or obtain a copy of it.
- Correct inaccurate information or request deletion.
- Receive certain information in a portable format.
- Opt out of sale, sharing, targeted advertising, or certain profiling.
- Limit certain uses of sensitive information or withdraw consent where processing relies on consent.
- Appeal a refusal to act on a privacy request.
Submit requests to privacy@flowsimple.co. We may request information reasonably necessary to verify identity, residency, and authority. An authorized agent may act where permitted by law, subject to proof of authorization. To appeal, reply to our decision with the subject “Privacy Appeal.” We do not discriminate against anyone for exercising an applicable privacy right.
11. US state privacy notices
For residents of states with comprehensive privacy laws, the categories collected appear in Section 2, sources in Section 3, purposes in Section 4, recipients in Section 5, and retention in Section 8. Depending on use, this may include identifiers, customer records, commercial information, internet activity, approximate or address-derived location, professional information, credentials, security information, user content, and service-related inferences.
We do not use sensitive personal information to infer characteristics or knowingly disclose personal information for third-party direct marketing. We recognize browser opt-out preference signals such as Global Privacy Control where legally required and technically applicable.
12. Subscriber responsibilities
- Provide required privacy notices to customers, workers, contractors, and other individuals.
- Collect, upload, disclose, and use information only when authorized and lawful.
- Configure roles appropriately and remove access when it is no longer needed.
- Avoid unnecessary sensitive information in notes, photos, messages, and attachments.
- Respond to requests involving Subscriber-controlled workspace information.
- Obtain consent required for communications, signatures, photos, location-related information, or marketing.
13. Children's privacy
FlowSimple is a business product and is not directed to anyone under 18. Account holders must be at least 18 and able to enter a business agreement. We do not knowingly collect children’s information directly for our own purposes. Subscribers must not use the Service to collect it without all authority, notices, and consent required by law.
14. US operation and data location
The Service is currently intended only for US businesses and customers. FlowSimple and its providers may process and store information in the United States and other locations where those providers operate. Any future international launch will be accompanied by the notices, agreements, transfer mechanisms, and rights processes we determine are required before offering the Service there.
15. Third-party services
The Service may link to Stripe, mapping applications, Subscriber websites, invoice pages, and other services. FlowSimple does not control their independent privacy, security, availability, or content. Review their notices before providing data. Stripe describes its practices in its Privacy Policy.
16. Changes to this policy
We may update this policy for changes in law, providers, the Service, or our practices. We will post the current version at flowsimple.co/privacy and update its date. If a change materially reduces privacy protections, we will provide additional notice where required.
17. Contact us
Privacy questions and requests may be sent to privacy@flowsimple.co. General support is available at support@flowsimple.co.
FlowSimpleMichigan, United States
For workspace information controlled by a Subscriber, contact that Subscriber first.